PT-2020-20238 · Themeum · Tutor Lms

Jinson Varghese Behanan

·

Published

2020-02-04

·

Updated

2022-01-01

·

CVE-2020-8615

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Tutor LMS plugin versions prior to 1.5.3
Description A CSRF issue can result in an attacker approving themselves as an instructor and performing other malicious actions, such as blocking legitimate instructors.
Recommendations For versions prior to 1.5.3, update to version 1.5.3 or later to resolve the issue.

Exploit

Fix

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-8615

Affected Products

Tutor Lms